API reference.
The REST API uses the same workspace permissions and review rules as Installens.
Check application status
Account and workspace access
Sign in through Installens to establish a session. Requests under /api/v1 use the session cookie and an X-Organization-Id header for the selected workspace. Knowing a workspace or job ID does not grant access.
GET /api/v1/jobs/page?limit=20
X-Organization-Id: {organizationId}Write requests must come from the configured application origin and use JSON. The workspace header does not replace authentication.
Managers organize work, technicians collect evidence for their assigned jobs, and reviewers make explicit decisions. Uploading, AI pre-checking and human approval remain separate states.
Read jobs and review history
Filter the job list with search, status, limit and cursor. Follow nextCursor while hasMore is true, preserving the same workspace and filters.
- GET
/api /v1 /jobs /page - Search and paginate the jobs you can access.
- GET
/api /v1 /jobs /{id} - Read current evidence, AI findings and review state.
- GET
/api /v1 /jobs /{id} /audit /page - Follow the job’s earlier activity.
Collect evidence and handle changes
Create an upload with file metadata, SHA-256 and an idempotency key. Transfer the original to the returned URL, then complete it. Reuse the same idempotency key when retrying the same upload.
- POST
/api /v1 /requirements /{id} /uploads - Create an upload and receive a URL for the original file.
- POST
/api /v1 /evidence /{id} /complete - Complete the upload and queue the evidence for checking.
409- The reviewed version or job revision changed. Refresh before deciding again.
429- Wait for the
Retry-Afterinterval before retrying.
Original files are retained when a review requires a correction.
Deliver a published version
Download the frozen report and delivery package for a published version. The ZIP includes originals, PDF, checksums and an expected/read CSV.
- GET
/api /v1 /jobs /{id} /reports /{version} /pdf - Download the PDF for this published report version.
- GET
/api /v1 /jobs /{id} /reports /{version} /zip - Download the versioned package and its supporting evidence.
Report shares require the recipient’s account by default. An explicitly selected recipient link lasts seven days and can be revoked. Its bearer credential is sent in the authorization header; keep it out of request URLs, logs and browser storage.
Interactive API documentation is available only when the deployment operator explicitly enables it in a non-production environment.